Skip to content
Original
Hacker News · AI Code Review 讨论· sanketsaurav·· 12/12/2025AI score66

DeepSource 发布 Autofix Bot:静态分析与 AI 混合的代码审查智能体

Original title: Show HN: Autofix Bot – Hybrid static analysis and AI code review agent

The title and summary in the selected language are awaiting translation.

AI overview

DeepSource(YC W20)团队发布 Autofix Bot,一个把静态分析与前沿 AI 智能体结合的代码审查智能体,面向 AI 编码工作流。其混合架构分三步:5000+ 确定性检查器建立高精度基线并由子智能体抑制误报,AI 审查以静态发现为锚点并调用 AST、数据流图、控制流、导入图等工具,最后由子智能体生成修复、静态校验后输出干净的 git patch。

Full text

Hi there, HN! We’re Jai and Sanket from DeepSource (YC W20), and today we’re launching Autofix Bot, a hybrid static analysis + AI agent purpose-built for in-the-loop use with AI coding agents. AI coding agents have made code generation nearly free, and they’ve shifted the bottleneck to code review. Static-only analysis with a fixed set of checkers isn’t enough. LLM-only review has several limitations: non-deterministic across runs, low recall on security issues, expensive at scale, and a tendency to get ‘distracted’. We spent the last 6 years building a deterministic, static-analysis-only code review product. Earlier this year, we started thinking about this problem from the ground up and realized that static analysis solves key blind spots of LLM-only reviews. Over the past six months, we built a new ‘hybrid’ agent loop that uses static analysis and frontier AI agents together to outperform both static-only and LLM-only tools in finding and fixing code quality and security issues. Today, we’re opening it up publicly. Here’s how the hybrid architecture works: - Static pass: 5,000+ deterministic checkers (code quality, security, performance) establish a high-precision baseline. A sub-agent suppresses context-specific false positives. - AI review: The agent reviews code with static findings as anchors. Has access to AST, data-flow graphs, control-flow, import graphs as tools, not just grep and usual shell commands. - Remediation: Sub-agents generate fixes. Static harness validates all edits before emitting a clean git patch. Static solves key LLM problems: non-determinism across runs, low recall on security issues (LLMs get distracted by style), and cost (static narrowing reduces prompt size and tool calls). On the OpenSSF CVE Benchmark [1] (200+ real JS/TS vulnerabilities), we hit 81.2% accuracy and 80.0% F1; vs Cursor Bugbot (74.5% accuracy, 77.42% F1), Claude Code (71.5% accuracy, 62.99% F1), CodeRabbit (59.4% accuracy, 36.19% F1), and Semgrep CE (56.9% accuracy, 38.26% F1). On secrets detection, 92.8% F1; vs Gitleaks (75.6%), detect-secrets (64.1%), and TruffleHog (41.2%). We use our open-source classification model for this. [2] Full methodology and how we evaluated each tool: https://autofix.bot/benchmarks You can use Autofix Bot interactively on any repository using our TUI, as a plugin in Claude Code, or with our MCP on any compatible AI client (like OpenAI Codex).[3] We’re specifically building for AI coding agent-first workflows, so you can ask your agent to run Autofix Bot on every checkpoint autonomously. Give us a shot today: https://autofix.bot . We’d love to hear any feedback! --- [1] https://github.com/ossf-cve-benchmark/ossf-cve-benchmark [2] https://huggingface.co/deepsource/Narada-3.2-3B-v1 [3] https://autofix.bot/manual/#terminal-ui

Source: Hacker News · AI Code Review 讨论 · news.ycombinator.com